chore(deps): update module github.com/cloudflare/circl to v1.6.3 [security]#58
chore(deps): update module github.com/cloudflare/circl to v1.6.3 [security]#58
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (2)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Closed automatically: bulk NumaryBot security cleanup |
Pull request was closed
This PR contains the following updates:
v1.6.1->v1.6.3CIRCL has an incorrect calculation in secp384r1 CombinedMult in github.com/cloudflare/circl
CVE-2026-1229 / GHSA-q9hv-hpm4-hj6x / GO-2026-4550
More information
Details
CIRCL has an incorrect calculation in secp384r1 CombinedMult in github.com/cloudflare/circl
Severity
Unknown
References
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
CIRCL has an incorrect calculation in secp384r1 CombinedMult
CVE-2026-1229 / GHSA-q9hv-hpm4-hj6x / GO-2026-4550
More information
Details
The CombinedMult function in the CIRCL ecc/p384 package (secp384r1 curve) produces an incorrect value for specific inputs. The issue is fixed by using complete addition formulas.
ECDH and ECDSA signing relying on this curve are not affected.
The bug was fixed in v1.6.3.
Severity
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/S:N/AU:Y/U:AmberReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
cloudflare/circl (github.com/cloudflare/circl)
v1.6.3: CIRCL v1.6.3Compare Source
CIRCL v1.6.3
Fix a bug on ecc/p384 scalar multiplication.
What's Changed
Full Changelog: cloudflare/circl@v1.6.2...v1.6.3
v1.6.2: CIRCL v1.6.2Compare Source
CIRCL v1.6.2
What's Changed
New Contributors
Full Changelog: cloudflare/circl@v1.6.1...v1.6.2
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Renovate Bot.